Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-657q-86jr-x2g6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.

Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.

EPSS

Процентиль: 54%
0.00309
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 18 лет назад

Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.

EPSS

Процентиль: 54%
0.00309
Низкий

Дефекты

CWE-20